Study: It’s Comically Easy To Identify ‘Anonymized’ Users In The ‘Metaverse’ With A Tiny Bit Of Motion Data
from the "anonymized"-doesn't-mean-anonymous dept
We’ve noted for a very long while how most of the explanations that corporations use to insist that your privacy is protected are effectively worthless.
For example, corporations will routinely inform you that it’s no big deal that they’re over-collecting and selling access to your browsing or location data to any idiot with a nickel because that data is “anonymized,” protecting your identity. In reality, that term means nothing, and study after study have shown it’s easy to identify you with only a few snippets of additional information.
With that in mind, a new study about user privacy in the virtual reality and augmented reality era (full study here) tracked 50,000 users in VR and found some interesting data. Most notably, that it takes incredibly little actual data collected from device microphones, cameras, and other tech to accurately identify a user’s real-world identity.
Like, very little:
The research analyzed more than 2.5 million VR data recordings (fully anonymized) from more than 50,000 players of the popular Beat Saber app and found that individual users could be uniquely identified with more than 94% accuracy using only 100 seconds of motion data.
Even more surprising was that half of all users could be uniquely identified with only 2 seconds of motion data. Achieving this level of accuracy required innovative AI techniques, but again, the data used was extremely sparse — just three spatial points for each user tracked over time.
Researchers found that the data they leave behind in virtual reality is more useful than a fingerprint to identify individuals. It also provides significantly more data to monetize, including a user’s height, handedness, gender, potential disability, strength, personal tics, etc.
Combine this data with the profiles already commonly being built at major companies and ad brokers, and you could see how this might be a bit of an issue in a country that’s literally too corrupt to pass even a basic privacy law for the internet era (there was just too much money to be made, sorry).
There have been so many studies at this point (including other previous studies of user VR data) showcasing how “anonymization” is a gibberish term. Yet the next time there’s a hack, breach, or huge batch of public data left unsecured in an Amazon cloud bucket, notice how quickly the term is immediately utilized as a catch all defense for sloppy privacy and security practices.
Filed Under: anonymization, AR, augmented reality, metaverse, privacy, privacy law, virtual reality, vr
Companies: facebook, meta


Comments on “Study: It’s Comically Easy To Identify ‘Anonymized’ Users In The ‘Metaverse’ With A Tiny Bit Of Motion Data”
Is this why Google Maps blots out my location with a big blue “Low Accuracy” blob until I turn on WiFi on my phone?
Re:
No. GPS is off.
“Study: It’s Comically Easy To Identify ‘Anonymized’ Users In The ‘Metaverse’ With A Tiny Bit Of Motion Data ”
How does one generate motion in the metaverse when they have no legs?
Re:
wut?
Re: Re:
““I know you’ve been waiting for this. Everyone has been waiting for this,” said a visually improved avatar version of Zuckerberg in Tuesday’s presentation. “But seriously, legs are hard, which is why other virtual reality systems don’t have them either.” ”
https://www.vox.com/recode/2022/10/11/23399439/metaverse-mark-zuckerberg-connect-avatar-legs-meta-microsoft-apple-vr-ar
Re: Assuming that your question is serious
The only way to be anonymous on the Internet is to not use it.
Re: Won't work
“The only way to be anonymous on the Internet is to not use it.”
Abstinence-only education doesn’t work. This won’t either, for the same reasons.
What is it referencing against?
Sure you can get the motion data from the game, but what are they referencing it against to find the real world identity? Is there a database of people’s movemenets already?
Are there security cams doing face and body tracking around that have this data available?
Re:
From the paper:
“Real-world” identity in this case means the username that generated the Beat Saber replay. I don’t think it would be possible to cross-reference this model with motion-tracking captured by non-VR applications, since the motion features used basically only exist when playing the game.
Privacy fear-mongers are forever trying to force their ludicrous concerns onto everyone else, and, thankfully so far, they have been largely failing. For the vast majority of people, “privacy” is of negative benefit, preventing online interaction that would benefit users by improving their experience with things useful to them.
Re:
Robert Mercer, is that you?
Re:
…said nobody mentally competent, ever.
Re:
“ludicrous concerns”
What, exactly, is ludicrous about privacy concerns?
““privacy” is of negative benefit”
Lame – very lame. Nebulous benefits? lol
Re:
“For the vast majority of people, “privacy” is of negative benefit”
Says someone depending on it to post here. Curious…
Re: Re:
I am otherwise automatically sent to moderation because the site host hates my viewpoints, and I don’t feel like waiting for hours or days to participate in the conversation. I’m well-known here to the people who dislike me, and am usually recognized by my use of the term “woke ideology”. If the host would stop trying to harass me into leaving, I would be happy to comment as signed-in.
Re: Re: Re:
…said nobody not on hallucinogens, ever.
Re: Re: Re:
Hyman.
You keep spouting Nazi ideology and you can’t even wonder WHY you’re being flagged, warned, told to leave and moderated?
You are not silenced EVERYWHERE. You are silenced HERE. Mike won’t be so petty as to drop a SLAPP on you or worse, even though you do deserve it.
And you keep continuing to BE A NAZI< even though by your own admission, you’re probably a Jew, or Polish, and your parents or grandparents have lived through World War 2 and the ACTUAL NAZI REGIME.
It just means that you are a shame to them. And worse.
Re: Re: Re:
Moderation for your inhumane opinions is harassment? Nah. Framing rejected.
Re: Re: Re:
Uh huh. You are trying to achieve a direct benefit from privacy. Only you and the people you like deserve privacy. Everyone else who wants privacy must be a whining baby.
ChatGPT can find anything on anyone I would think.
Re:
ChatGPT can make up anything on anyone. Finding actual correct data is a different matter.
Re: Re:
More accurately – it’s been trained on data that was online during the training period. That doesn’t mean results are accurate (it can return results based on the training, but they might not be accurate depending on the query), or out of date (something changed after the training period).
If an inaccurate result is returned, it doesn’t mean it’s “making it up”, it means it’s returning an inaccurate result based on the dataset it’s using. Which just means that you have to deal with machine learning as suggestion not a fact, which is good advice no matter what you’re trying to search for.
Re:
ChatGPT can’t find anything that wasn’t available online to anyone using search engines during the period that it was being trained.
So virtual reality has something to offer after all
All this focus on the “metaverse” always sounded idiotic to me. Decades-old reheated soup. However:
Oh, so maybe Zuck does know what he’s doing. When everyone pointed out Facebook is a massive threat to privacy, a mass surveillance mechanism and a way to sell personal data to advertisers, he went “Oh, all that sounds great! Is there any way to do it even more?”. And the answer apparently was virtual reality.